PkgRadar

Composer · packagist.org

oat-sa/extension-tao-testqti

Known Indicator Filename: oat-sa-extension-tao-testqti-ccc36b7/views/build/grunt/bundle.js

Why PkgRadar flagged v50.3.3

SeveritySignalEvidence
highKnown Indicator Filenameoat-sa-extension-tao-testqti-ccc36b7/views/build/grunt/bundle.js · oat-sa-extension-tao-testqti-ccc36b7/views/build/grunt/bundle.js
mediumPhp Shell Callexec / system / passthru / shell_exec / proc_open — process spawning. · oat-sa-extension-tao-testqti-ccc36b7/manifest.php
mediumPhp Shell Callexec / system / passthru / shell_exec / proc_open — process spawning. · oat-sa-extension-tao-testqti-ccc36b7/models/classes/class.QtiTestCompiler.php
mediumPhp Shell Callexec / system / passthru / shell_exec / proc_open — process spawning. · oat-sa-extension-tao-testqti-ccc36b7/scripts/install/CreateTableForToolsStateStorage.php
mediumRemote Payloadmatched "cUrl " · oat-sa-extension-tao-testqti-ccc36b7/test/unit/models/classes/scale/ScaleHandlerTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v50.3.3Review302026-05-27

Block this in CI

PkgRadar gates oat-sa/extension-tao-testqti (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer oat-sa/[email protected]